{"id":61166,"date":"2026-07-28T22:01:53","date_gmt":"2026-07-28T22:01:53","guid":{"rendered":"https:\/\/www.theregister.com\/a\/5280001"},"modified":"2026-07-28T22:01:53","modified_gmt":"2026-07-28T22:01:53","slug":"looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\/","title":{"rendered":"Looks like JFrog&#8217;s 0-days let OpenAI&#8217;s models hack Hugging Face"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/image.theregister.com\/232611.jpg?imageId=232611&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\" class=\"ff-og-image-inserted\"><\/div>\n<div data-element-guid=\"d11159dd-82a3-4c53-901c-d41dec75505c\" readability=\"30.777202072539\">\n<p class=\"kicker \">Security<\/p>\n<p class=\"subtitle \">The vendor won&#8217;t confirm or deny<\/p>\n<\/p><\/div>\n<div data-element-guid=\"4c9dc5d9-c886-4348-bf4a-01d0dc71377d\" readability=\"98.686274509804\">\n<p>We now have a better idea of how OpenAI&#8217;s models broke out of their cages to attack Hugging Face. The rogue models found zero-day vulnerabilities in JFrog\u2019s universal binary repository manager Artifactory around the time they escaped, according to JFrog CTO Yoav Landman.<\/p>\n<p>While Landman doesn\u2019t outright admit that the JFrog flaws were the <a href=\"https:\/\/www.theregister.com\/ai-and-ml\/2026\/07\/22\/openai-admits-it-was-the-source-of-the-agent-swarm-that-attacked-hugging-face\/5275939\">zero-days that OpenAI\u2019s models found and exploited<\/a>, ultimately allowing them to <a href=\"https:\/\/www.theregister.com\/cyber-crime\/2026\/07\/20\/frontier-llms-couldnt-help-hugging-face-fight-off-evil-agents\/5275168\">breach the massive model mart<\/a>, it definitely looks and quacks like a duck &#8211; err, frog.&nbsp;<\/p>\n<p>Landman says OpenAI&#8217;s models discovered the Artifactory zero-days during a security evaluation. The AI giant notes the incident occurred while its models were being evaluated on the&nbsp;<a href=\"https:\/\/www.theregister.com\/ai-and-ml\/2026\/07\/28\/openais-agent-siege-forced-significant-rebuild-at-hugging-face\/5279577\">ExploitGym benchmark<\/a>.<\/p>\n<p>\u201cDuring a security evaluation, OpenAI\u2019s models identified previously unknown zero-day vulnerabilities in self-hosted Artifactory installations that could be exploited to gain unintended internet access,\u201d Landman <a href=\"https:\/\/jfrog.com\/blog\/jfrog-and-openai-collaboration-on-zero-day-security-findings\/\" rel=\"nofollow\">said<\/a> on Monday.<\/p>\n<p><a href=\"https:\/\/jfrog.com\/blog\/what-is-artifactory-jfrog\/\" rel=\"nofollow\">JFrog Artifactory<\/a> is a central platform that organizations use to store and distribute all the software artifacts across their supply chains. It supports more than 60 package formats including Docker, Maven, npm, PyPI, Helm, and AI\/ML models.&nbsp;<\/p>\n<p>OpenAI \u201cresponsibly and immediately\u201d disclosed the vulnerabilities to JFrog, Landman continued. \u201cOur security team treated the report with the urgency it deserved, as a genuine zero-day unknown to the world, and moved accordingly. We developed, validated, and released a fix for all JFrog customers, self-hosted and cloud alike.\u201d<\/p>\n<div data-element-guid=\"afe083ca-6701-48e9-9bd8-f8827dd7fb42\" class=\"lab4 column articleList layout_vertical imageLayout_left small-12 large-12 small-abs-12 large-abs-12 abs_grid_12 grid-vas-start mobile-grid-vas-start\">\n<div class=\"content border_width_0 border_width_mobile_0 border-radius-48 border-radius-mobile_48\">\n<h2 class=\"article-list-title t19 font-RobotoCondensed\">MORE CONTEXT<\/h2>\n<\/p><\/div>\n<\/div>\n<p>On Monday, JFrog released the <a href=\"https:\/\/docs.jfrog.com\/releases\/docs\/artifactory-self-managed-releases#artifactory-7161\" rel=\"nofollow\">fixed versions<\/a>, and credited OpenAI researchers for reporting at least eight of the now-patched Artifactory vulnerabilities:&nbsp;<a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-65617\" rel=\"nofollow\">CVE-2026-65617<\/a>, <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-65925\" rel=\"nofollow\">CVE-2026-65925<\/a>, <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-65921\" rel=\"nofollow\">CVE-2026-65921<\/a>, <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-65923\" rel=\"nofollow\">CVE-2026-65923<\/a>, <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-66018\" rel=\"nofollow\">CVE-2026-66018<\/a>, <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-66014\" rel=\"nofollow\">CVE-2026-66014<\/a>, <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-66015\" rel=\"nofollow\">CVE-2026-66015<\/a>, and <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-65924\" rel=\"nofollow\">CVE-2026-65924<\/a>.<\/p>\n<p><span class=\"italic m-italic \" data-lab-italic=\"italic\">The Register<\/span> asked JFrog whether at least some of these were abused by OpenAI\u2019s rogue models to access the internet and compromise Hugging Face, but the DevOps firm isn\u2019t talking.<\/p>\n<p>JFrog&#8217;s admission comes about a week after <a href=\"https:\/\/www.theregister.com\/security\/2026\/07\/24\/openai-hugging-face-attack-doesnt-mean-agents-are-evil-unless-you-tell-them-to-be\/5277881\">OpenAI said two of its models<\/a>, GPT-5.6 Sol and a second pre-release model, escaped their testing sandbox during a security evaluation designed to test their cyber capabilities. During this test, the models found a way to access the open internet, then broke into Hugging Face and accessed private information and stole some credentials.<\/p>\n<p>\u201cWhile operating in our sandboxed testing environment, our models spent a substantial amount of inference compute finding a way to obtain open Internet access, in pursuit of solving the evaluation problem,\u201d OpenAI <a href=\"https:\/\/openai.com\/index\/hugging-face-model-evaluation-security-incident\/\">said<\/a> on July 21. <\/p>\n<p>\u201cTo gain access, the models identified and exploited a zero-day vulnerability (which we\u2019ve now responsibly disclosed to the vendor) in the package registry cache proxy.\u201d<\/p>\n<p><span class=\"italic m-italic \" data-lab-italic=\"italic\">The Register<\/span> also reached out to OpenAI and asked if JFrog is the vendor referenced in its blog, but did not receive any response.&nbsp;<\/p>\n<p>Luckily, your humble vulture is headed to Vegas in a week for Hacker Summer Camp, so we will be sure to test our betting prowess in the appropriate environment. Without guardrails, of course. \u00ae<\/p>\n<\/p><\/div>\n<p><img decoding=\"async\" src=\"https:\/\/image.theregister.com\/?imageId=232611&#038;width=800\">READ MORE <a href=\"https:\/\/www.theregister.com\/security\/2026\/07\/28\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\/5280001\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> The vendor won&#8217;t confirm or deny READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":61167,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[307],"class_list":["post-61166","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register","tag-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Looks like JFrog&#039;s 0-days let OpenAI&#039;s models hack Hugging Face 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Looks like JFrog&#039;s 0-days let OpenAI&#039;s models hack Hugging Face 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-28T22:01:53+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/image.theregister.com\/232611.jpg?imageId=232611&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Looks like JFrog&#8217;s 0-days let OpenAI&#8217;s models hack Hugging Face\",\"datePublished\":\"2026-07-28T22:01:53+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\\\/\"},\"wordCount\":508,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face.jpg\",\"keywords\":[\"Security\"],\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\\\/\",\"name\":\"Looks like JFrog's 0-days let OpenAI's models hack Hugging Face 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face.jpg\",\"datePublished\":\"2026-07-28T22:01:53+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face.jpg\",\"width\":100,\"height\":70},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/security\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Looks like JFrog&#8217;s 0-days let OpenAI&#8217;s models hack Hugging Face\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Looks like JFrog's 0-days let OpenAI's models hack Hugging Face 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\/","og_locale":"en_US","og_type":"article","og_title":"Looks like JFrog's 0-days let OpenAI's models hack Hugging Face 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2026-07-28T22:01:53+00:00","og_image":[{"url":"https:\/\/image.theregister.com\/232611.jpg?imageId=232611&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Looks like JFrog&#8217;s 0-days let OpenAI&#8217;s models hack Hugging Face","datePublished":"2026-07-28T22:01:53+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\/"},"wordCount":508,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/07\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face.jpg","keywords":["Security"],"articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\/","url":"https:\/\/www.threatshub.org\/blog\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\/","name":"Looks like JFrog's 0-days let OpenAI's models hack Hugging Face 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/07\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face.jpg","datePublished":"2026-07-28T22:01:53+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/07\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/07\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face.jpg","width":100,"height":70},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/looks-like-jfrogs-0-days-let-openais-models-hack-hugging-face\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Security","item":"https:\/\/www.threatshub.org\/blog\/tag\/security\/"},{"@type":"ListItem","position":3,"name":"Looks like JFrog&#8217;s 0-days let OpenAI&#8217;s models hack Hugging Face"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61166","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=61166"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61166\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/61167"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=61166"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=61166"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=61166"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}